Splunk Enterprise Security

Issue with Identity Management lookup expansion with ESS v 3.0 and Splunk 6.0.1 on Windows Platforms

dshakespeare_sp
Splunk Employee
Splunk Employee

Customers running Splunk ESS 3.0 / Splunk 6.0.1 on Windows platforms may experience issues with lookup expansions/creation not working correctly in Identity Management.

There may also be further problems with the Asset/Identity Investigators dashboard eg Asset/identity information is displayed in the upper part of the screen, but the swim lanes at the bottom just show a constant stream of progress dots which never complete.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post